Highlights Security
Protecting (personal) data is a priority. We have implemented robust security measures, which are the cornerstone of our commitment to privacy, to keep all data safe.
The following are several key security highlights:
1. Adequate measures to protect against security threats
We conduct an annual IT risk analysis and Business Impact Assessment (BIA) to ensure that security and privacy risks are adequately covered by appropriate measures. These assessments also evaluate whether our measures still comply with the latest privacy legislation and the current state of cybersecurity threats. Our defined measures are based on international standards from the AICPA (SOC 2 Trust Service Criteria for service organizations, March 2020 update), ISO (ISO27001: 2022), and BSI (C5:2020 minimum requirements for secure cloud computing).
To ensure all relevant security and privacy measures have been implemented, we commissioned an independent IT audit firm (KPMG) to perform an audit. This audit results in a SOC 2® assurance report, demonstrating that the required security and privacy measures have been implemented and have been effective over the past 12 months.
2. Strong access controls
We maintain adequate password requirements and assign authorizations based on the "least privilege access" and "need to know" principles. Additionally, we have implemented multi-factor authentication (MFA) to minimize the risk of unauthorized access.
3. Close monitoring of products and IT infrastructure
We continuously perform manual penetration tests and vulnerability scans—both internally and externally—using professional security tools to ensure vulnerabilities are identified on our platform and websites. We utilize a vulnerability management process to ensure that any identified issues are resolved promptly, preventing "open doors" for hackers.
4. Encrypted data and protected backups
Data on our platform is encrypted both "at rest" and "in transit" using adequate protocols to ensure hackers cannot access the information. We have also implemented backup protection as an additional measure to combat ransomware attacks.
5. NextGen protection against viruses and malware
We maintain NextGen anti-virus and anti-malware software on all laptops and servers to stop threats on the spot and actively monitor emerging threats.
6. Intakes ensure security and privacy by design
For all new initiatives, changes to existing processes, or involvement of (new) third parties, a mandatory security and privacy intake and assessment is required. This guarantees that "security and privacy by design" are implemented for any new personal or confidential data collected or processed.
7. Adequate hardening
Hardening is a vital security measure that raises the overall security level by providing a minimum security baseline for IT assets. Consequently, we have implemented the CIS and AWS Foundational Benchmarks baseline for IT assets in our AWS hosting environment, as well as a CIS baseline for our laptops.
8. Strong vendor management
Because vendors can be a weak point in a security framework, we only select external suppliers that meet our standards. During the contracting phase, we ensure all relevant privacy measures are in place (including a Data Processing Agreement) and assess whether the supplier has implemented sufficient security. We annually review our suppliers for compliance with our internal security standards based on their SOC 2 or other provided security reports.
If you would like more information about our security program, please contact your account manager or visit our Trust Center.